Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
Windshift
ID: 82be24fe68596702112898966fa3b3bd51544
Cybercrime
State-Sponsored
Threat types: Intrusion, Surveillance, Phishing
Progress: 35%
Completeness: 28%
Freshness: 50%
Operation zone: UNKNOWN
Aliases
Limited alias preview
No aliases registered.
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East. Ref: https://attack.mitre.org/groups/G0112/
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1036.001 | Invalid Code Signature | TA0005 |
|
| T1059.005 | Visual Basic | TA0002 |
|
| T1071.001 | Web Protocols | TA0011 |
|
| T1204.001 | Malicious Link | TA0002 |
|
| T1204.002 | Malicious File | TA0002 |
|
| T1417.001 | Keylogging | TA0031 TA0035 |
|
| T1518.001 | Security Software Discovery | TA0007 |
|
| T1521.001 | Symmetric Cryptography | TA0037 |
|
| T1547.001 | Registry Run Keys / Startup Folder | TA0003 TA0004 |
|
| T1566.001 | Spearphishing Attachment | TA0001 |
|
| T1566.002 | Spearphishing Link | TA0001 |
|
| T1566.003 | Spearphishing via Service | TA0001 |
|
| T1627.001 | Geofencing | TA0030 |
|
| T1628.003 | Conceal Multimedia Files | TA0030 |
|
| T1632.001 | Code Signing Policy Modification | TA0030 |
|
| T1633.001 | System Checks | TA0030 |
|
| T1636.003 | Contact List | TA0035 |
|
| T1636.004 | SMS Messages | TA0035 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.